Hacker News new | ask | show | jobs
by JimmaDaRustla 4661 days ago
I believe there is a PCI requirement that a company's system must be evaluated once every three months by a PCI approved vendor to ensure that data is being kept secure.

To me, it seems kind of contradictory because if a company is being approved by said vendors, then how could they be found non-compliant in a breach? Maybe the quarterly vendor assessment isn't mandatory. digs through documents

EDIT: This quarterly scan by an ASV and only evaluates the network in regards to external IP addresses, so it does not check anything regarding how the data is stored/transferred.

2 comments

My PCIDSS provider runs nessus once a quarter. It's found a few bugs but it's not an evaluation of anything other than my web facing server.
Nor a properly documented procedure seems to exist for random people (me) to report blatant PCI-DSS violation they stumbled upon.

PCI-DSS is barely better than security theater, with so litte effort spent on finding violations...